NPI targeting and HCP programmatic advertising

HCP Identity Matching: How an NPI Becomes an Addressable Audience

HCP identity matching turns an NPI list into reachable devices and logins. How emails, site logins, device graphs, and hashed IDs work, and why rates differ.

Christian Guerrero Published 6 min read Part 6 of 10

The short answer

HCP identity matching links each NPI on your list to digital identifiers a media system can use: hashed professional emails, endemic site logins, cookies, mobile ad IDs, or IDs inside a device graph. Some links are deterministic (a known login or email), some are probabilistic (inferred from device and location signals). Match rates differ between partners because their sources, matching rules, freshness thresholds, and denominators all differ.

The NPI is a number in a registry. An ad server does not know what to do with it. Something has to connect that number to a browser, an app, an email inbox, or a logged-in session. That connection is identity matching, and it is the step where most of the variation in HCP campaign performance begins.

How does HCP identity matching work?

At a high level, a partner maintains a table that says, in effect, "NPI 1234567890 is associated with these identifiers." When you send your list, the partner joins it to that table. Every NPI with at least one associated identifier counts as matched. The matched identifiers become the audience segment pushed to a DSP or used directly on the partner's own inventory.

The table is built from several kinds of source, and each partner has a different mix.

Where do the identity links come from?

Professional site logins

Endemic publishers and clinical tools ask providers to register. Many verify credentials against the NPPES registry or a licensed physician database. Every time that provider logs in, the publisher sees a known NPI on a known device. These links are the strongest available, and they refresh naturally as people keep using the site.

Professional email

Data companies and publishers hold emails associated with NPIs. When a provider opens or clicks an email, a cookie or device ID can be associated with that NPI. The email itself can also be hashed and matched to other platforms that hold the same hashed email.

Onboarding

Onboarding takes offline records (name, practice address, email) and matches them against an identity graph to return digital IDs. The graph may be built from logins across many sites, from consumer data, or from a mix. The identity graph evaluation guide lists questions to ask about how a graph was built.

Device graphs and probabilistic inference

Some links are inferred. A device that regularly appears at a practice's IP address during working hours, and also at a home address linked to a provider, might be assigned to that provider. This adds scale, but the confidence is lower and the logic is rarely shared in detail.

Deterministic vs. probabilistic matching

A deterministic match rests on an explicit identifier the provider used: a login, an email address. A probabilistic match rests on a model's judgement that a device probably belongs to the provider. Both have uses. The problem is when they are blended into one number and sold as one thing. The site's existing article on deterministic vs. probabilistic HCP identity goes deeper into how to treat each, and 1:1 HCP targeting covers how to test a partner's claims.

What is hashing, and does it make data anonymous?

Hashing runs an identifier such as an email address through a one-way function (SHA-256 is common) and produces a fixed string. Two parties that hash the same email the same way get the same string, so they can match without exchanging the raw address. That is useful. It is not anonymization. The same email always produces the same hash, so the hash still identifies a person to anyone who holds the original. Treat hashed emails as personal data in contracts and data flows. Industry groups such as the Network Advertising Initiative publish codes that address how members handle this kind of data.

Why do match rates differ so much?

Send the same 10,000 NPIs to three partners and you may get three very different match rates. The reasons are usually some combination of the following.

ReasonWhat it looks likeQuestion to ask
Different sourcesAn endemic publisher matches only its users; a graph partner matches broadlyWhat share of matches came from each source type?
Different match rulesOne partner counts any linked ID; another requires a confirmed recent linkWhat is the minimum evidence for a match?
Freshness thresholdsOld links still counted as matchesWhat is the median age of the links?
Different denominatorsRate calculated on "valid NPIs" or "NPIs in our database" instead of your full listMatched count divided by what number?
Specialty mixSpecialties with heavy endemic site use match betterCan you show match rate by segment?
Probabilistic expansionModeled links included without being labeledIs any of this match probabilistic?

The site's piece on why HCP audience match rates differ works through examples of each.

A match is not the same as reach

A matched NPI has at least one identifier on file. That identifier still has to appear on inventory the campaign can buy during the flight, and the bid still has to win. A partner with a 70% match rate can easily deliver to fewer than half of your list. Ask for exposed reach against the full list as a separate number. The NPI targeting guide shows the full step-down from list to exposure.

What good matching practice looks like

  1. Send one clean list version to every partner, with NPIs stored as text.
  2. Ask each partner to report matched count by source type and by segment.
  3. Ask for link age and refresh cadence in writing.
  4. Require probabilistic matches to be flagged or excluded.
  5. Calculate every match rate yourself using your full list as the denominator.
  6. Measure overlap between partners before adding more data. See how to measure audience overlap.

Practical takeaway

Next time a partner quotes a match rate, reply with three questions: matched count divided by what number, what share of the matches are deterministic, and how old the median link is. The answers will tell you more about the audience than the rate itself.

Frequently asked questions

What is HCP identity matching?

HCP identity matching is the process of linking a provider's NPI to digital identifiers such as hashed emails, cookies, mobile ad IDs, or publisher logins, so media can be delivered to that provider. The result is an addressable audience built from your target list.

Why do HCP match rates differ between partners?

Each partner holds different identity sources, uses different matching rules, and often reports match rate against a different denominator. One partner may count any linked identifier as a match while another requires a recently confirmed one.

Is hashing an email the same as anonymizing it?

No. Hashing turns an email into a fixed string, but the same email always produces the same hash, which is why it works for matching. It reduces exposure of the raw address but should be treated as personal data under most contracts and privacy rules.

Sources

External guidance and platform documentation change. Links were current at publication; check them again before relying on them for a decision.

Editorial note. Analysis and frameworks are the author's own and do not represent Acxiom or any current or former employer, client, or named platform. Examples labeled hypothetical or illustrative are not results from real campaigns. Nothing here is legal, regulatory, or medical advice.

Working through this decision on a real plan?

I work on health and pharma data, identity, and activation, after five years running HCP and DTC programmatic agency-side. Happy to talk through how this applies to your situation.